🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

Render

United States · PaaS · https://render.com

Sovereignty score22.7%
Global (unweighted)24.1%
Overall SEAL
SEAL-0 No Sovereignty
SOV-1 Strategic Sovereignty13.6SEAL-0
SOV-2 Legal & Jurisdictional Sovereignty12.6SEAL-1
SOV-3 Data & AI Sovereignty30.0SEAL-0
SOV-4 Operational Sovereignty12.6SEAL-0
SOV-5 Supply Chain Sovereignty7.2SEAL-1
SOV-6 Technology Sovereignty30.0SEAL-0
SOV-7 Security & Compliance Sovereignty43.1SEAL-1
SOV-8 Environmental Sustainability43.8SEAL-1

SOV-1 · Strategic Sovereignty 13.6% · SEAL-0 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highRender Services, Inc. is incorporated and headquartered in San Francisco, USA; no EU legal entity controls the company (src: https://render.com/terms).
SOV-1.2Change of control risk3. Somewhat likely takeover/transfer to non-EU sovereign entity63/125SEAL-4lowVC-backed US startup ($258M raised, ~$1.5B valuation); acquisition by a non-EU entity is a realistic exit path but not imminent.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumRoadmap is controlled by the US company; EU customers can only influence via public feature-request/feedback channels, no governance body.
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highFunding is almost entirely non-EU US venture capital (General Catalyst, Bessemer, Georgian, Addition, 01A, South Park Commons).
SOV-1.5EU economic contribution1. Minimal0/125SEAL-4mediumUS-based company with US workforce and US ownership; EU economic contribution is minimal beyond reselling AWS Frankfurt capacity.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4highNo evidence of participation in Gaia-X, IPCEI-CIS or any EU strategic program.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo evidence of alignment with EU industrial strategies; positioning is global/US developer market.
SOV-1.8Resilience to cut-off2. Service would stop, with delay for customer reaction31/125SEAL-0mediumNo own_stack: PaaS on non-EU hyperscalers (AWS/GCP); a US cut-off or AWS withdrawal halts the service, leaving only a migration window -> SOV-1.8 opt2 (seal 0).

SOV-2 · Legal & Jurisdictional Sovereignty 12.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction1. Non-EU only0/167SEAL-1highTerms of service are governed by US (California, San Francisco courts) law; the contracting entity is US, not subject to exclusive EU jurisdiction (src: https://render.com/terms).
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highconsistency (cluster norm 2.2=opt2): US-incorporated, no EU trustee/shielding structure; GDPR DPA/SCC mitigation clauses exist but residual exposure to US CLOUD Act/FISA remains -> opt2 (seal 1) (src: https://render.com/dpa).
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highconsistency (cluster norm 2.3=opt2): US-incorporated (no immunity) -> subject to US CLOUD Act/FISA, can be compelled to grant access including EU-region data without notification in specific national-security cases (gag orders) -> opt2 (seal 1).
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowconsistency (cluster norm 2.4=opt2): US export-control regimes (EAR/OFAC) apply; no EU-MS shielding and no >50% EU revenue dominance -> opt2 (seal 1).
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highThe platform IP (orchestration, control plane) is developed and owned by the US company; effectively entirely outside the EU.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highIP is held by the US parent under US (single-country) law.

SOV-3 · Data & AI Sovereignty 30.0% · SEAL-0 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys1. Provider only0/200SEAL-0mediumRender manages encryption at rest using underlying cloud provider keys; no customer-managed/BYOK key control is offered, so the provider holds the keys.
SOV-3.2Transparent data flows & access logs2. Basic incomplete logs50/200SEAL-1lowRender provides service/audit logs but not comprehensive real-time customer-controlled data-access logs of provider/sub-processor access.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowconsistency (cluster norm 3.3=opt3): deletion follows documented internal policy/DPA commitments with no independently verified cryptographic proof-of-erasure -> opt3 (internal validation per policy, seal 1).
SOV-3.4Data location strictly in EU/EEA2. Partly EU, significant third-country reliance50/200SEAL-0mediumNo eu_exclusive: Frankfurt is one of several regions (Oregon/Ohio/Virginia/Singapore), no contractual EU-only guarantee, US-operated control plane processes globally -> global-default product, significant third-country reliance, SOV-3.4 opt2 (seal 0) (src: https://render.com/docs/regions).
SOV-3.5AI services sovereignty3. Mixed: auditable/open-source AI, foreign chips100/200SEAL-2lowconsistency (cluster norm: no in-scope first-party AI service, like Platform.sh): Render offers no AI/ML service; any inference runs on foreign accelerators in the underlying hyperscalers -> opt3 (mixed/foreign chips, seal 2).

SOV-4 · Operational Sovereignty 12.6% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumRender uses standard Docker/container runtimes and documented data export; portability is feasible but no formal migration service to sovereign infra.
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1highCritical platform engineering and operations are run by the US-based team; the EU region depends on AWS plus US operators.
SOV-4.3Skill availability in the EU1. Global team, mainly non-EU0/167SEAL-1mediumEngineering/SRE staff are predominantly US-based; no indication of a dedicated EU operations workforce.
SOV-4.4Support channels1. Global, majority outside EU0/167SEAL-1mediumSupport is global and US-centered (San Francisco HQ); no EU-based support guarantee.
SOV-4.5Documentation & knowledge transfer1. Global/non-EU exposure0/167SEAL-0lowNo eu_ops: documentation and knowledge bases are global/US-hosted with no EU-only repository enforcement -> SOV-4.5 opt1 (seal 0).
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2mediumCritical dependency on AWS (EU) and GCP (US) sub-processors; loss of these would stop the service after a migration delay.

SOV-5 · Supply Chain Sovereignty 7.2% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)1. No disclosure0/143SEAL-1mediumRender owns no hardware; physical components belong to AWS/GCP and are not disclosed to Render's customers as a bill of materials.
SOV-5.2Manufacturing location1. Fully foreign, black box0/143SEAL-1mediumUnderlying servers are manufactured/operated by US hyperscalers (foreign, black box from Render's perspective).
SOV-5.3Embedded code/firmware provenance1. No disclosure0/143SEAL-4lowFirmware/embedded code of the underlying hardware (hyperscaler-controlled) is not disclosed.
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2mediumforeign_core: control-plane software is proprietary US-developed (open-source components, partial disclosure), maintained outside the EU -> SOV-5.4 opt2 (seal 2).
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1mediumSoftware build and release pipeline is controlled and executed by the US company, not in the EU.
SOV-5.6Single point of dependency1. Only non-EU vendors/facilities0/143SEAL-1highSingle point of dependency on non-EU vendors (AWS, GCP) and the US parent for the entire platform.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome transparency via SOC 2/ISO 27001 sub-processor lists, but the full supply chain is not customer-auditable.

SOV-6 · Technology Sovereignty 30.0% · SEAL-0 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces3. Mixed (partial openness)100/200SEAL-2mediumRender exposes REST APIs, standard Git/Docker workflows and Blueprint specs, mixing open practices with proprietary platform constructs.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumPartial adoption of open standards (Docker, OCI containers, standard protocols) but no policy mandating open standards across all core services.
SOV-6.3Open source availability1. Fully closed-source, vendor-controlled0/200SEAL-2mediumRender's platform/control plane is closed-source and vendor-controlled; it consumes open source but the product itself is not open.
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSome public architecture insight via docs and engineering blog, but no deep architecture transparency or customer co-design.
SOV-6.5HPC sovereignty1. Imported black-box HPC0/200SEAL-0lowNo EU HPC; any high-performance/GPU compute relies on imported black-box hyperscaler hardware.

SOV-7 · Security & Compliance Sovereignty 43.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2highcerts: ISO 27001:2022 + SOC 2 Type II (no C5/ENS/SecNumCloud/EUCS/Common Criteria EAL); per key ISO 27001 + SOC 2 maps to opt3 (EAL2-equiv, seal 2) (src: https://render.com/docs/certifications-compliance).
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)4. Partial compliance to most107/143SEAL-4mediumGDPR DPA offered and SOC 2/ISO 27001 audited, but no demonstrated NIS2/DORA compliance; partial compliance to most relevant regimes (src: https://render.com/docs/certifications-compliance).
SOV-7.3EU-based SOC & incident handling1. SOC/IR outside EU0/143SEAL-1lowconsistency (US-centric cluster norm): security operations and incident response are run by the US-based team with no dedicated EU SOC -> opt1 (SOC outside EU, seal 1).
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowconsistency (cluster norm 7.4=opt3): customers get a logs/metrics monitoring portal, but provider retains primary control and no guarantee of EU-stored immutable logs -> opt3 (basic monitoring portal, seal 1).
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure via GDPR DPA breach-notification commitments; GDPR-aligned but no real-time CSIRT/ENISA sharing.
SOV-7.6Maintenance autonomy3. Moderate autonomy (notice + testing, except zero-day)72/143SEAL-4lowRender performs platform maintenance with customer notice; managed PaaS gives moderate autonomy with scheduled/notified maintenance.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1mediumNo audit_rights: independent assurance limited to third-party SOC 2/ISO audits and shared reports; no full audit by the contracting authority or independent EU body -> SOV-7.7 opt2 (seal 1).

SOV-8 · Environmental Sustainability 43.8% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowRuns on AWS/GCP data centers which publish PUE around 1.1-1.2 with efficiency roadmaps; Render inherits hyperscaler efficiency but publishes none itself -> opt3 (PUE<1.5 + roadmap) (src: https://www.google.com/about/datacenters/efficiency/).
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowUnderlying AWS/GCP facilities have documented hardware reuse/recycling programs; Render itself owns no hardware -> opt3 (documented program) (src: https://sustainability.aboutamazon.com/products-services/aws-cloud).
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowRender does not publish its own environmental report; only basic inherited reporting via hyperscaler sustainability disclosures -> opt2 (basic reporting, seal 1).
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowAWS Frankfurt and GCP use a mix of renewable and grid energy with renewable matching; energy supply is a mix of EU and non-EU sources (src: https://www.google.com/about/datacenters/cleanenergy/).